Cisco IOS 防火墙鉴别代理缓存溢出漏洞

发表于:2007-06-23来源:作者:点击数: 标签:
信息提供: 安全 公告(或线索)提供热线:51cto.editor@gmail.com 漏洞类别: 边界条件错误 攻击类型: 远程攻击 发布日期: 2005-09-07 更新日期: 2005-10-12 受影响系统: Cisco IOS 12.4 T Cisco IOS 12.4 MR Cisco IOS 12.4 Cisco IOS 12.3 YW Cisco I

   



信息提供:

安全公告(或线索)提供热线:51cto.editor@gmail.com

漏洞类别:

边界条件错误

攻击类型:

远程攻击

发布日期:

2005-09-07

更新日期:

2005-10-12

受影响系统:

Cisco IOS 12.4 T

Cisco IOS 12.4 MR

Cisco IOS 12.4

Cisco IOS 12.3 YW

Cisco IOS 12.3 YU

Cisco IOS 12.3 YT

Cisco IOS 12.3 YS

Cisco IOS 12.3 YQ

Cisco IOS 12.3 YK

Cisco IOS 12.3 YJ

Cisco IOS 12.3 YI

Cisco IOS 12.3 YG

Cisco IOS 12.3 YF

Cisco IOS 12.3 YD

Cisco IOS 12.3 YA

Cisco IOS 12.3 XY

Cisco IOS 12.3 XW

Cisco IOS 12.3 XU

Cisco IOS 12.3 XS

Cisco IOS 12.3 XR

Cisco IOS 12.3 XQ

Cisco IOS 12.3 XM

Cisco IOS 12.3 XL

Cisco IOS 12.3 XK

Cisco IOS 12.3 XJ

Cisco IOS 12.3 XI

Cisco IOS 12.3 XH

Cisco IOS 12.3 XG

Cisco IOS 12.3 XF

Cisco IOS 12.3 XE

Cisco IOS 12.3 XD

Cisco IOS 12.3 XC

Cisco IOS 12.3 XB

Cisco IOS 12.3 XA

Cisco IOS 12.3 T

Cisco IOS 12.3 JK

Cisco IOS 12.3 JA

Cisco IOS 12.3 BW

Cisco IOS 12.3 BC

Cisco IOS 12.3 B

Cisco IOS 12.3

Cisco IOS 12.2 ZL

Cisco IOS 12.2 ZF

Cisco IOS 12.2 SXF

Cisco IOS 12.2 SH

Cisco IOS 12.2 SG

Cisco IOS 12.2 SEC

安全系统:

无 Cisco IOS 12.4 (2)T

Cisco IOS 12.4 (2)MR

Cisco IOS 12.4 (1)

Cisco IOS 12.3 (9d)

Cisco IOS 12.3 (9a)BC7

Cisco IOS 12.3 (8)YI1

Cisco IOS 12.3 (8)YG2

Cisco IOS 12.3 (8)T9

Cisco IOS 12.3 (7)XR4

Cisco IOS 12.3 (7)XI4

Cisco IOS 12.3 (7)T10

Cisco IOS 12.3 (7)JA

Cisco IOS 12.3 (6e)

Cisco IOS 12.3 (5e)

Cisco IOS 12.3 (4)XK4

Cisco IOS 12.3 (4)XG5

Cisco IOS 12.3 (3h)

Cisco IOS 12.3 (2)XE4

Cisco IOS 12.3 (2)XC3

Cisco IOS 12.3 (2)XA5

Cisco IOS 12.3 (2)JK

Cisco IOS 12.3 (15)

Cisco IOS 12.3 (14)YU

Cisco IOS 12.3 (14)YT

Cisco IOS 12.3 (14)YQ

Cisco IOS 12.3 (14)T2

Cisco IOS 12.3 (13a)

Cisco IOS 12.3 (12b)

Cisco IOS 12.3 (11)YW

Cisco IOS 12.3 (11)YS

Cisco IOS 12.3 (11)YK1

Cisco IOS 12.3 (11)YF2

Cisco IOS 12.3 (11)XL3

Cisco IOS 12.3 (11)T6

Cisco IOS 12.3 (10d)

Cisco IOS 12.2 (13)ZH8

漏洞报告人:

Cisco

漏洞描述:

Bugtraq ID:14770

Cisco IOS Firewall Authentication Proxy 存在一个缓存溢出漏洞。成功的攻击可导致拒绝服务或潜在执行任意代码。

该漏洞影响 FTP 和远程登录协议,但不影响 HTTP。

测试方法:

解决方法:

Cisco 已发布了安全公告,请参看下面链接获得升级信息:

http://www.cisco.com/public/sw-center/sw-ios.shtml



Cisco 发布升级公告 66269,说明了IOS 12.2ZH 不受影响, IOS 12.2SH 和12.2ZF版本受影响:

Cisco Security Advisory: Cisco IOS Firewall Authentication Proxy for FTP and Tel (Cisco)



原文转自:http://www.ltesting.net